Floating Network Identity Management via Distributed Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dynamic networking environments, such as cloud networks with multiple user devices, pose challenges for configuration and network management due to their ephemeral nature and the difficulty in maintaining unambiguous identities for computing resources as they join or leave the network automatically.

Innovation Solution

The implementation of a floating network system using distributed agents on hosts across multiple networks, where each node is generated with unique credentials based on a trust relationship path from the root node, enabling dynamic identity management and communication policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud instances are automatically provisioned and decommissioned to accommodate operational load, then the scalability and adaptability of the network is improved, but the difficulty of maintaining unambiguous identities for computing resources increases

Engineering Contradiction:
ImprovescalabilityVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning identity credentials (such as certificates or tokens) in the image or configuration template of cloud instances before they are deployed. When cloud instances are automatically provisioned, they inherit these pre-configured identity credentials, enabling them to join the network immediately with unambiguous identities without requiring post-provisioning identity configuration. This resolves the contradiction by enabling scalability through automatic provisioning while maintaining simple identity management through pre-configuration.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple user devices are allowed to join the network dynamically, then the versatility and user freedom of the network is improved, but the complexity of network configuration and management increases

Engineering Contradiction:
Improveuser device compatibilityVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a standardized identity credential system that works across all types of user devices (cloud instances, personal computers, mobile devices). Instead of requiring device-specific configuration procedures, the system uses a universal credential format and authentication mechanism that any device can adopt. This resolves the contradiction by enabling diverse user devices to join the network freely while keeping configuration management simple through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud instances are rapidly provisioned and decommissioned, then the responsiveness and automation level of the network is improved, but the reliability of maintaining consistent identity information decreases

Engineering Contradiction:
Improveprovisioning speedVSAvoididentity consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies copying by creating identity credentials as immutable templates or images that are replicated to each cloud instance during provisioning. Instead of generating unique identity information dynamically for each instance (which could lead to inconsistencies), the system copies verified, pre-approved identity templates. This ensures that every cloud instance, regardless of when it is provisioned or decommissioned, maintains consistent and reliable identity information that adheres to network policies, while still enabling rapid automated provisioning.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8856308B1Cloud scale automatic identity management
Publication Date: 2014.10.07 APPLE INC
  • US8856308B1 patent drawing
  • US8856308B1 patent drawing
  • US8856308B1 patent drawing

AI summary

Embodiments are directed to towards cloud scale automatic identity management. A floating network may be established using agents operative on hosts across one or more networks. Each node of the floating network is resident on host (computer or cloud instance) that includes an agent configured to perform one or more networking tasks that establish the floating network. Parent nodes may be nodes designated as points in the floating network for adding additional nodes. Accordingly, each parent node includes at least one parent agent that includes at least parent credentials. Agent installers provided to a host may generate a child agent for the host that includes child credentials generated based on its parent credentials. An unambiguous identity value for the new child node may be determined by tracing a trust relationship path from the child node to the root node of the floating network.